General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

scp export with unexported-only option

Hi,I would like to know how to use the unexported-only feature with this command:scp export log traffic to user@ip:/path/test.csv start-time equal 2016/08/14@00:00:00 end-time equal 2016/08/14@23:59:59 Also is it possible to invoke it through the API? Thanks!

amagri by L1 Bithead
  • 5121 Views
  • 4 replies
  • 0 Likes

Static Routes not Working

I have a network with in my network that I am trying to control access with user-id in the palo alto. Before I can do this I need to get routing working. The routing works just fine up to the palo alto in my test environment. Each interface can talk to the next hop on the otherside but traffic isn't routing across the interfaces. I can not p...

trees by L1 Bithead
  • 9266 Views
  • 4 replies
  • 0 Likes

application not working.

I had a customer connecting to an application from trust to untrust. It was working and then suddenly stopped working.I could see in the logs it was coming as port 443 and application -incomplete and then next day it started working with port 443 and application ssl. Any logical reason why this would happen. Running 7.0.6 PA200.

about mtu

Hello all, There is a problem with a smb traffic(very very slow)For the related source and dest. ip address 2 filter is configured and show counter output has : flow_fwd_mtu_exceeded 9 3 info flow forward Packets lengths exceeded MTUflow_ipfrag_frag 18 6 info flow ipfrag IP fragments transmitted There is no drop.All devices through the way has m...

PanIst by L3 Networker
  • 2673 Views
  • 1 replies
  • 0 Likes

Resolved! Blocking macro-enabled Office files (docm, xlsm, etc)

The available file types that can be filtered doesn't include Office documents with macros (docm, xlsm, etc). These are being used now to sneak garbage into the network. Is there a way to ID them or are they on the horizon for inclusion in the file blocking filters? An innovative way that is being used is to create an xlsm file with a malicio...

gleduc by L1 Bithead
  • 14150 Views
  • 4 replies
  • 0 Likes

Resolved! Domain names in Security Policy

Does anyone know if it's possible to use a domain in a security policy? I know that I can use FQDN but what happens if I need to allow a wider range, such as *.zoom.us? Can this be done or am I out of luck?

BPry by Cyber Elite
  • 5859 Views
  • 4 replies
  • 0 Likes

GlobalProtect - Client Certificates Deployment

Greetings, I have used the following article to distribute client certificates for GlobalProtect: https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Issue-Certificates-to-GlobalProtect-Devices/ta-p/53642 My understanding is that with this method of certificate distribution, all client machines will have the same client certificat...

Creid by L0 Member
  • 2736 Views
  • 2 replies
  • 0 Likes

QoS and interfaces - some conception advice needed

Hello I will migrate fom PA200 to PA500. I have some local networks (DMZ, Wifi for students, Wifi for stuff, LANs)I need to use QoS but I need some advice with that. I know that I can controll only on outgoing interfaces but I have no idea how to get it working with one condition: I wouldnt limit traffic from/to my local servers in DMZ. Now I ha...

_slv_ by L4 Transporter
  • 4723 Views
  • 6 replies
  • 0 Likes

Resolved! VM-300 Steps validation

Can some please these are the initial steps for setting up VM-300 in NSX? 1) Register auth codes for VM's2) Download the base-image on he VM that will host VM-300 firewall3) When download of sofware is complete I should UUID an dCPUUID4) After base configuration in VmWare NSX is completed I will be about to go to portal and register the new V...

Mounting Orientation for PA-500 (Vertical - Wall Mount)

Does anyone know if the PA-500 can be mounted using a 19" Rack mall mount bracket?(Front = Up) (Back = Down).Using something similar to this?https://www.startech.com/Server-Management/Racks/2U-19in-Steel-Vertical-Wall-Mount-Equipment-Rack-Bracket~RK219WALLV

mjdut18 by L0 Member
  • 1984 Views
  • 1 replies
  • 0 Likes

User-ID causing high CPU

Hello People, My client has receently upgraded to 7.1.3 and now the management plane is constantly running 100% on all firewalls. This is the following message displayed and filling up the userid.log 2016-07-22 16:43:38.660 +0100 Error: pan_user_id_agent_msgs_queue_msg(pan_user_id_agent_msgs.c:58): failed to insert msg into sending msg list We...

Looking to Learn Palo Alto

Looking for advice on cheapest way to learn Palo Alto? I am a consultant and dont have any Palo Alto licenses. Is a VM lab license affordable, is there trials or is ebay the best option? Thanks in advance!

daveram by L0 Member
  • 7519 Views
  • 8 replies
  • 0 Likes
  • 24452 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels